Valeo · security governance / February 2026

Who owns the evidence? Not necessarily the person who currently has the file

Evidence ownership was often confused with whoever had last sent the document. That model was operationally wrong, so responsibility was separated by role and source system.

2 min read
Valeo · security governance
ownershipevidenceRACIprocess

Situation

Audit requests often begin in email and naturally land with the person who previously supplied a similar file. That can create false ownership: a coordinator appears responsible for technical data that is actually produced by another system and another team. When that person is unavailable, the process stalls.

Approach

I split responsibility into three questions: who produces the data, who validates its meaning, and who coordinates its inclusion in the audit package. Where possible, roles or teams replaced individual names. The register then stopped asking who sent the file last and started recording where the evidence should be obtained again.

Outcome

Person-dependent requests decreased and substitution became easier. Technical teams retained responsibility for content, while governance retained responsibility for traceability and deadlines. The separation also removed a great deal of ambiguity during escalations.